tech:notes_kubernetes_k8s_-_securite
Différences
Ci-dessous, les différences entre deux révisions de la page.
| Les deux révisions précédentesRévision précédenteProchaine révision | Révision précédente | ||
| tech:notes_kubernetes_k8s_-_securite [2025/10/04 16:00] – Jean-Baptiste | tech:notes_kubernetes_k8s_-_securite [2025/11/06 11:33] (Version actuelle) – Jean-Baptiste | ||
|---|---|---|---|
| Ligne 5: | Ligne 5: | ||
| Voir : | Voir : | ||
| + | * [[Scan de vulnérabilité pour les images de conteneurs]] | ||
| * https:// | * https:// | ||
| * https:// | * https:// | ||
| Ligne 10: | Ligne 11: | ||
| * https:// | * https:// | ||
| * Kube-bench | * Kube-bench | ||
| + | * https:// | ||
| + | * https:// | ||
| + | * https:// | ||
| + | * https:// | ||
| + | |||
| + | Containers ! | ||
| + | * https:// | ||
| + | * https:// | ||
| + | |||
| Ligne 100: | Ligne 110: | ||
| - | | + | ## Outils analyse sécu |
| + | |||
| + | Voir : | ||
| + | * m9sweeper | ||
| + | |||
| + | |||
| + | ### Kube bench | ||
| + | |||
| + | Step 1: Download the official job manifest | ||
| + | |||
| + | Clone the kube-bench repo or grab job.yaml from the GitHub releases page. | ||
| + | ~~~bash | ||
| + | git clone https:// | ||
| + | cd kube-bench | ||
| + | |||
| + | # ou | ||
| + | kubectl apply -f https:// | ||
| + | ~~~ | ||
| + | |||
| + | Step 2: Apply the job to your cluster | ||
| + | ~~~bash | ||
| + | kubectl apply -f job.yaml | ||
| + | ~~~ | ||
| + | |||
| + | Step 3: Watch the pod until it shows as Completed | ||
| + | ~~~bash | ||
| + | kubectl get pods -w | ||
| + | ~~~ | ||
| + | |||
| + | Step 4: Review the results | ||
| + | ~~~bash | ||
| + | #kubectl logs -l job-name=kube-bench | ||
| + | kubectl logs pod/ | ||
| + | ~~~ | ||
| + | |||
| + | ~~~bash | ||
| + | podman run --pid=host -v / | ||
| + | ~~~ | ||
| + | |||
| + | |||
| + | ### kubescape | ||
| + | |||
| + | Voir : | ||
| + | * https:// | ||
| + | |||
| + | Install | ||
| + | ~~~bash | ||
| + | kubectl krew update | ||
| + | kubectl krew install kubescape | ||
| + | ~~~ | ||
| + | |||
| + | Scan | ||
| + | ~~~bash | ||
| + | kubectl kubescape scan | ||
| + | kubescape scan --format html --output results.html | ||
| + | ~~~ | ||
| + | |||
| + | |||
| + | Voir Trivy [[Scan de vulnérabilité pour les images de conteneurs]] | ||
| + | |||
| + | |||
| + | |||
| + | |||
tech/notes_kubernetes_k8s_-_securite.1759586401.txt.gz · Dernière modification : de Jean-Baptiste
